Thursday, April 24, 2025
HomeCyber AttackZoom Flaws Can Be Exploited By Hackers by Sending Specially Crafted Messages

Zoom Flaws Can Be Exploited By Hackers by Sending Specially Crafted Messages

Published on

SIEM as a Service

Follow Us on Google News

Four critical security vulnerabilities have been fixed recently in the popular video conferencing service Zoom. These security flaws could be exploited by the threat actors to send specially crafted XMPP messages to another user and then run malicious code on that server using the compromised user’s computer.

The vulnerabilities that are addressed recently range from 5.9 to 8.1 on the severity scale. All four security flaws were discovered and reported in February 2022 by Ivan Fratric of Google Project Zero.

Bugs Detected & Fixed

It should be noted that the company now addressed the following vulnerabilities:-

- Advertisement - Google News
  1. CVE ID: CVE-2022-22784
  2. Description: Improper XML Parsing in Zoom Client for Meetings
  3. CVSS score: 8.1
  4. Severity: High
  1. CVE ID: CVE-2022-22785
  2. Description: Improperly constrained session cookies in Zoom Client for Meetings
  3. CVSS score: 5.9
  4. Severity: Medium
  1. CVE ID: CVE-2022-22786
  2. Description: Update package downgrade in Zoom Client for Meetings for Windows
  3. CVSS score: 7.5
  4. Severity: High
  1. CVE ID: CVE-2022-22787
  2. Description: Insufficient hostname validation during server switch in Zoom Client for Meetings
  3. CVSS score: 5.9
  4. Severity: Medium

Exploitation

Among all of them, CVE-2022-22784 with a CVSS score of 8.1 is the most severe flaw fixed by Zoom. This vulnerability is related to improper XML parsing in the Zoom Client for Meetings.

In the exploitation of the vulnerability, the threat actor is able to create a distinct message context and break away from the current XMPP message context. In this way, different actions are performed by the user’s client on the receiving end.

Zoom’s chat feature is built upon the XMPP standard and therefore enables a high level of interaction. As a result of exploiting the aforementioned vulnerabilities, the threat actors can pose as regular users to steal sensitive information. 

This will result in arbitrary code execution due to the downgrade attack caused by a suspicious server. XML parsers in the software’s client and server can be found to have inconsistencies by cyberattackers.

The victim of such an attack will receive XMPP stanzas which can be used to communicate with the attackers.

A Zoom client with a less secure version of the software can be served up via a man-in-the-middle server that hijacks the software update mechanism.

In a nutshell, Zoom is releasing patches to fix two high-severity flaws, CVE-2022-22782 and CVE-2022-22783 which were found approximately one month ago. 

The vulnerabilities could lead to escalation of privileges within the on-premise Meetings service and disclosure of memory contents, both of which could lead to local privilege escalation. 

Zoom’s macOS app was also victimized by a downgrade attack (CVE-2022-22781) which was also fixed. To mitigate any potential threat arising out of active exploitation of the vulnerability, it is recommended that all users of the application update to the latest version (5.10.0) of the app.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Redis DoS Flaw Allows Attackers to Crash Servers or Drain Memory

A high-severity denial-of-service (DoS) vulnerability in Redis, tracked as CVE-2025-21605, allows unauthenticated attackers to crash...

Google Warns: Threat Actors Growing More Sophisticated, Exploiting Zero-Day Vulnerabilities

Google’s Mandiant team has released its M-Trends 2025 report, highlighting the increasing sophistication of...

Critical Langflow Flaw Enables Malicious Code Injection – Technical Breakdown Released

A critical remote code execution (RCE) vulnerability, identified as CVE-2025-3248 with a CVSS score...

GitLab Releases Critical Patch for XSS, DoS, and Account Takeover Bugs

GitLab, a leading DevOps platform, has released a critical security patch impacting both its...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Google Warns: Threat Actors Growing More Sophisticated, Exploiting Zero-Day Vulnerabilities

Google’s Mandiant team has released its M-Trends 2025 report, highlighting the increasing sophistication of...

Critical Langflow Flaw Enables Malicious Code Injection – Technical Breakdown Released

A critical remote code execution (RCE) vulnerability, identified as CVE-2025-3248 with a CVSS score...

Hackers Exploit NFC Technology to Steal Money from ATMs and POS Terminals

In a disturbing trend, cybercriminals, predominantly from Chinese underground networks, are exploiting Near Field...